Manage Connections
The Manage Connections page is where Site Administrators authorize the imaging devices that may send to the Flywheel-hosted inbound DIMSE C-STORE receiver, share the DICOM Router's own certificate, and monitor incoming activity. This guide walks through each task in the Flywheel web app.
Applies to Flywheel-hosted inbound DIMSE C-STORE
These steps apply to inbound DIMSE C-STORE, the Flywheel-hosted DICOM receiver introduced in Flywheel 22.2, which receives DICOM over the public internet and secures it with mutual TLS. For an overview, see the DICOM Router.
Before you begin
- Inbound DIMSE C-STORE must be enabled for your site. If it is not, contact Flywheel Support.
- You need Site Administrator access to the Flywheel web app.
- For each device you plan to authorize, collect its public certificate, the hostname or IP it connects from (as Flywheel sees it — your public or egress address if you use NAT), and its Application Entity Title (AET). See Connectivity Requirements for how to gather these.
Open the Manage Connections page
- In the Flywheel web app, go to Interfaces → Connector to open Connector Details.
- Select Manage Connections.

The top of the page identifies the DICOM Router, labeled Flywheel Connector, with its Hostname, Port, and AET. The sending side uses these as the DICOM destination. The page lists each AET that the DICOM Router accepts. See Manage the DICOM Router's AETs. Below it, Authorized Devices lists each device that is allowed to send, with its mTLS Cert Expiration and Last Activity.
Manage the DICOM Router's AETs
The DICOM Router accepts DICOM studies addressed to any of its configured AETs. Each additional AET is an alias for the same receiver: all of them share the DICOM Router's hostname, port, and certificate. Adding AETs lets a single DICOM Router appear to sending devices as several separate DICOM destinations.
The DICOM Router's data processing rules can match on the AET that each study was sent to (the called_aet field), so each AET can route studies to a different Flywheel project. These rules are an import rule set dedicated to the DICOM Router. To edit them, select Configure Data Processing Rules on Connector Details. For example, a scanner can be configured with two destinations, ROUTER1 and ROUTER2, that both point to the DICOM Router, and rules like the following send each one to its own project:
Each additional AET still has to be registered on both sides: add it to the DICOM Router as described below, and add it as a destination on the sending device or appliance.
Every DICOM Router has a default AET that Flywheel configures. Site Administrators can add and remove additional AETs from the top of the Manage Connections page. DICOM limits an AE title to 16 characters.
Site Administrators can also manage AETs with the New CLI (flyw):
Use flyw admin connectors list to find the connector ID.
Share the DICOM Router's public certificate
With mutual TLS, the sending side also verifies Flywheel's identity, so it needs the DICOM Router's public certificate. Select Get Public Certificate, then choose Copy Certificate or Download Certificate, and provide it to whoever configures the device or appliance.

Authorize a device
Each device is authorized individually — trust is anchored to that device's certificate, not to whoever issued it. See Secure Connections (Mutual TLS) for the authorization model.
- Select Authorize New Device.
- Enter a Device Name, the Hostname/IP the device connects from, and its AET. Port is optional.
- Under Provide the Public Certificate of the device, paste the certificate, or select Upload Certificate to load a certificate file (
.crt,.cer,.pem, or.der). - Select Save.

Register the endpoint that actually connects
If a proxy or gateway makes the connection on the device's behalf, register the appliance's certificate, hostname or IP, and AET — not those of the device sitting behind it.
Add a private certificate authority (optional)
If your devices use privately-issued certificates, you can add your private certificate authority (CA) so Flywheel can validate them — for example, confirming the certificate chain and expiry.
- Select Add Private CA.
- Paste the CA certificate, or select Upload Private CA Certificate to load a file (
.crt,.cer,.pem, or.der). - Select Save.

A private CA validates certificates; it does not authorize them
Adding a CA does not authorize every certificate that CA issues. Each device is still authorized individually by its own registered certificate. See Secure Connections (Mutual TLS).
Monitor DICOM Router activity
Inbound DIMSE C-STORE builds on Flywheel's Bulk Import. The DICOM Router handles the DICOM-specific receiving, then launches a standard import to route each received study into its destination project — one import job per study.
Connector Details lists recent Connector Activity from the DICOM Router's point of view, so it is the best place to confirm that expected studies have arrived. It includes studies that have been received but not yet imported, and it reflects the success or failure of each study's import. Each row shows the Started At time, the Status, the sending Device, the Study Description, and the Destination Project and Group.

Select Go to Details on a row to open that study's import job in its destination project. The import job covers the import step — de-identification, malware scanning, grouping and zipping, upload to Flywheel Core, and conflict handling — and gives a more detailed view of that stage.
Where to look
In normal operation, received data flows straight through and appears in Flywheel Core, and in the destination project's Imports list, without any action on this page. You generally only need Connector Activity when a study seems to be missing. Together, the two views trace each study end to end, from arrival at the DICOM Router through import.
Related pages
- Connectivity Requirements — what your devices or appliances must support.
- Secure Connections (Mutual TLS) — how Flywheel authenticates each device.
- DICOM Router — overview of DICOM Router and inbound DIMSE C-STORE.